Suspicious
Suspect

d66685c1ff0ea4e93724b4e86459a8a0

PE Executable
MD5: d66685c1ff0ea4e93724b4e86459a8a0
Size: 3.49 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score High
MD5 d66685c1ff0ea4e93724b4e86459a8a0
Sha1 cf66fff1c1d02e0b19fd8faab55930d0ea499df0
Sha256 e8b13c084533e4ae24ea404d7bd849554af93071e62c61ef47f7f98cd8d62e31
Sha384 35f153028e1cbfb5cf66bdc3c1952e63f82f35a78f6d5556a713fe1c40f771fe1e56c9ee3535d68e77fd43f937ec98b7
Sha512 1a4f03b0b60bcce9042d50a1738c539ca9f754ef711f0c446ca8b1338660efc287a29ebb72a333b39f11b3c07c86fda7c304865c3b667d0ac00ee9d6a544ca9d
SSDeep 49152:KpEgjRxxyLxdhXNPEY+XY0y0/ALL+jDjVZepRloRjXYe7ynhYMAHJbWWuuqN3ov:SNfELxbSYAoLLCZ3NYeqhYMkbRui
TLSH 12F5234966D18C35CA525D3482300AB443779F993A91F383FDA83CB737B37D968A64CA
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
server1.exe
Full Name
server1.exe
EntryPoint
System.Void server.Module2::main()
Scope Name
server1.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
server1
Assembly Version
1.1.0.9
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
32
Main Method
System.Void server.Module2::main()
Main IL Instruction Count
89
Main IL
nop <null>
ldc.i4 1432654620
stloc.s V_4
ldloc.s V_4
not <null>
not <null>
dup <null>
stloc.3 <null>
ldc.i4.7 <null>
rem.un <null>
switch dnlib.DotNet.Emit.Instruction[]
br IL_012E: ret
call System.String server.Module2::_05994CA8F9A040EE_()
ldc.i4 -1746344613
br.s IL_0042: call System.String <Module>::_5E8060E209784A91_<System.String>(System.IntPtr)
call System.String <Module>::_5E8060E209784A91_<System.String>(System.IntPtr)
call System.String server.Module2::_67155E3BF3704C80_(System.String,System.String)
stsfld System.String server.Module2::Hex
ldsfld System.String server.Module2::Hex
call System.Byte[] server.Module2::_365849E59FC2487B_(System.String)
stsfld System.Byte[] server.Module2::Bytes
call System.Object server.Module2::_20F925A97ACE4614_()
stloc.0 <null>
ldc.i4 549996963
stloc.s V_5
ldloc.3 <null>
ldc.i4 -854625
mul <null>
ldloc.s V_5
xor <null>
br.s IL_0006: stloc.s V_4
call System.Object server.Module2::_BD758BFC843C46FE_()
stloc.2 <null>
ldc.i4 -467680589
stloc.s V_8
ldloc.3 <null>
ldc.i4 -328023
mul <null>
ldloc.s V_8
xor <null>
br IL_0006: stloc.s V_4
call System.Object server.Module2::_4274CE594DB54221_()
stloc.1 <null>
ldloc.1 <null>
ldsfld System.Byte[] server.Module2::Bytes
call System.Object server.Module2::_D895528C9A6B4E92_()
call System.Object server.Module2::_474F5D756C3D4E17_(System.Object)
call System.String server.Module2::_201682605BC94A01_(System.Object)
call System.Boolean server.Module2::_9EA0B1EFA6BA409E_(System.Object,System.Byte[],System.String)
pop <null>
ldc.i4 1144325982
stloc.s V_7
ldloc.3 <null>
ldc.i4 -909532
mul <null>
ldloc.s V_7
xor <null>
br IL_0006: stloc.s V_4
ldloc.0 <null>
ldsfld System.Byte[] server.Module2::Bytes
call System.Object server.Module2::_D895528C9A6B4E92_()
call System.Object server.Module2::_474F5D756C3D4E17_(System.Object)
call System.String server.Module2::_201682605BC94A01_(System.Object)
call System.Boolean server.Module2::_F0A40884FE224914_(System.Object,System.Byte[],System.String)
pop <null>
ldc.i4 2122239973
stloc.s V_6
ldloc.3 <null>
ldc.i4 -815664
mul <null>
ldloc.s V_6
xor <null>
br IL_0006: stloc.s V_4
ldloc.2 <null>
ldsfld System.Byte[] server.Module2::Bytes
call System.Object server.Module2::_D895528C9A6B4E92_()
call System.Object server.Module2::_474F5D756C3D4E17_(System.Object)
call System.String server.Module2::_201682605BC94A01_(System.Object)
call System.Boolean server.Module2::_0AD2F773BCEC4D4F_(System.Object,System.Byte[],System.String)
pop <null>
ldc.i4 169487098
stloc.s V_9
ldloc.3 <null>
ldc.i4 -716122
mul <null>
ldloc.s V_9
xor <null>
br IL_0006: stloc.s V_4
ret <null>
Module Name
server1.exe
Full Name
server1.exe
EntryPoint
System.Void server.Module2::main()
Scope Name
server1.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
server1
Assembly Version
1.1.0.9
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
32
Main Method
System.Void server.Module2::main()
Main IL Instruction Count
89
Main IL
nop <null>
ldc.i4 1432654620
stloc.s V_4
ldloc.s V_4
not <null>
not <null>
dup <null>
stloc.3 <null>
ldc.i4.7 <null>
rem.un <null>
switch dnlib.DotNet.Emit.Instruction[]
br IL_012E: ret
call System.String server.Module2::_05994CA8F9A040EE_()
ldc.i4 -1746344613
br.s IL_0042: call System.String <Module>::_5E8060E209784A91_<System.String>(System.IntPtr)
call System.String <Module>::_5E8060E209784A91_<System.String>(System.IntPtr)
call System.String server.Module2::_67155E3BF3704C80_(System.String,System.String)
stsfld System.String server.Module2::Hex
ldsfld System.String server.Module2::Hex
call System.Byte[] server.Module2::_365849E59FC2487B_(System.String)
stsfld System.Byte[] server.Module2::Bytes
call System.Object server.Module2::_20F925A97ACE4614_()
stloc.0 <null>
ldc.i4 549996963
stloc.s V_5
ldloc.3 <null>
ldc.i4 -854625
mul <null>
ldloc.s V_5
xor <null>
br.s IL_0006: stloc.s V_4
call System.Object server.Module2::_BD758BFC843C46FE_()
stloc.2 <null>
ldc.i4 -467680589
stloc.s V_8
ldloc.3 <null>
ldc.i4 -328023
mul <null>
ldloc.s V_8
xor <null>
br IL_0006: stloc.s V_4
call System.Object server.Module2::_4274CE594DB54221_()
stloc.1 <null>
ldloc.1 <null>
ldsfld System.Byte[] server.Module2::Bytes
call System.Object server.Module2::_D895528C9A6B4E92_()
call System.Object server.Module2::_474F5D756C3D4E17_(System.Object)
call System.String server.Module2::_201682605BC94A01_(System.Object)
call System.Boolean server.Module2::_9EA0B1EFA6BA409E_(System.Object,System.Byte[],System.String)
pop <null>
ldc.i4 1144325982
stloc.s V_7
ldloc.3 <null>
ldc.i4 -909532
mul <null>
ldloc.s V_7
xor <null>
br IL_0006: stloc.s V_4
ldloc.0 <null>
ldsfld System.Byte[] server.Module2::Bytes
call System.Object server.Module2::_D895528C9A6B4E92_()
call System.Object server.Module2::_474F5D756C3D4E17_(System.Object)
call System.String server.Module2::_201682605BC94A01_(System.Object)
call System.Boolean server.Module2::_F0A40884FE224914_(System.Object,System.Byte[],System.String)
pop <null>
ldc.i4 2122239973
stloc.s V_6
ldloc.3 <null>
ldc.i4 -815664
mul <null>
ldloc.s V_6
xor <null>
br IL_0006: stloc.s V_4
ldloc.2 <null>
ldsfld System.Byte[] server.Module2::Bytes
call System.Object server.Module2::_D895528C9A6B4E92_()
call System.Object server.Module2::_474F5D756C3D4E17_(System.Object)
call System.String server.Module2::_201682605BC94A01_(System.Object)
call System.Boolean server.Module2::_0AD2F773BCEC4D4F_(System.Object,System.Byte[],System.String)
pop <null>
ldc.i4 169487098
stloc.s V_9
ldloc.3 <null>
ldc.i4 -716122
mul <null>
ldloc.s V_9
xor <null>
br IL_0006: stloc.s V_4
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙